File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:36
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward wrapper for a third-party website screenshot API and clearly discloses its API key, network use, credit costs, and returned image data.
Install this if you are comfortable using Scavio as the screenshot provider. Treat SCAVIO_API_KEY as a secret, avoid sending private or sensitive URLs, and start with the cheaper normal mode before using ultra because successful captures consume credits.
Detected: suspicious.exposed_secret_literal